diff options
author | Li Zhijian | 2019-01-17 13:49:01 +0100 |
---|---|---|
committer | Paolo Bonzini | 2019-02-05 16:50:18 +0100 |
commit | 0c249ff71c094c0e009e2ccaef5237af3610b0fb (patch) | |
tree | 855e1f40abe9e930f66749b83ab3a2831992c546 /hw/core/qdev-properties-system.c | |
parent | ui: vnc: finish removing TABs (diff) | |
download | qemu-0c249ff71c094c0e009e2ccaef5237af3610b0fb.tar.gz qemu-0c249ff71c094c0e009e2ccaef5237af3610b0fb.tar.xz qemu-0c249ff71c094c0e009e2ccaef5237af3610b0fb.zip |
unify len and addr type for memory/address APIs
Some address/memory APIs have different type between
'hwaddr/target_ulong addr' and 'int len'. It is very unsafe, especially
some APIs will be passed a non-int len by caller which might cause
overflow quietly.
Below is an potential overflow case:
dma_memory_read(uint32_t len)
-> dma_memory_rw(uint32_t len)
-> dma_memory_rw_relaxed(uint32_t len)
-> address_space_rw(int len) # len overflow
CC: Paolo Bonzini <pbonzini@redhat.com>
CC: Peter Crosthwaite <crosthwaite.peter@gmail.com>
CC: Richard Henderson <rth@twiddle.net>
CC: Peter Maydell <peter.maydell@linaro.org>
CC: Stefano Garzarella <sgarzare@redhat.com>
Signed-off-by: Li Zhijian <lizhijian@cn.fujitsu.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Diffstat (limited to 'hw/core/qdev-properties-system.c')
0 files changed, 0 insertions, 0 deletions